Heights Finance Breach Exposes Data of 1.2 Million Borrowers
Consumer lender Heights Finance Holdings has begun notifying more than 1.2 million people that their personal and financial data was lifted by hackers who got into a third-party cloud storage platform the company used for customer records.
The breach was discovered in early May. Heights says its core loan management systems were untouched, which is the sort of silver lining companies always mention while glossing over the fact that enormous amounts of sensitive customer data walked out the door anyway.
The haul was comprehensive. Names, addresses, email addresses, phone numbers, Social Security numbers, government IDs, driver's licence numbers, bank account details, dates of birth. Essentially everything a fraudster needs to have a very productive few months at someone else's expense.
The scope is wider than just current Heights customers. Former borrowers of Curo Management and its associated brands are also potentially affected, as are people who simply enquired about or applied for a loan product, including through third parties. You don't even need to have been a Heights customer to find yourself in this.
State attorney general filings put the affected numbers at 734,828 in Texas and 486,463 in South Carolina, with handfuls of individuals in New Hampshire and Vermont rounding out the total past 1.2 million.
Heights is offering the standard post-breach consolation prize: 24 months of free credit monitoring and identity protection. The company says its dark web monitoring hasn't found the stolen data circulating yet, which is mildly reassuring but hardly a guarantee.
No ransomware or extortion group has publicly claimed responsibility, and Heights hasn't named any suspects. Outside cybersecurity specialists were brought in to investigate and the incident was reported to federal law enforcement, so the usual boxes have been ticked.
The third-party platform at the centre of this has since been secured, apparently. Cold comfort for the million-plus people now waiting to see whether their Social Security numbers turn up somewhere they shouldn't.